From 37c4fb8847d2774118254fb095a6bd075033ce9c Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Wed, 9 Sep 2026 23:07:14 +0000 Subject: [PATCH] docs: record Aikido scan-release gate as merged in PR #75 Socket PR reviews and Actions-secret inventory remain unchecked; those need maintainer access this token does not have. Co-authored-by: Jared Wray --- DEFENSE_IN_DEPTH.md | 2 +- SECURITY.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/DEFENSE_IN_DEPTH.md b/DEFENSE_IN_DEPTH.md index 928a6cd..34878c9 100644 --- a/DEFENSE_IN_DEPTH.md +++ b/DEFENSE_IN_DEPTH.md @@ -44,7 +44,7 @@ Profile: npm library · public ## 6. Security tooling - [x] Aikido runs on every build — verified 2026-09-09 (PR #65: Aikido Security: check code) -- [ ] Aikido release gate: the release workflow's stage-publish job `needs:` a passing `scan-release` (PR #75 pending) +- [x] Aikido release gate: the release workflow's stage-publish job `needs:` a passing `scan-release` — PR #75 - [ ] Socket reviews every PR that changes dependencies ## 7. Repository lockdown diff --git a/SECURITY.md b/SECURITY.md index 20598f4..1d4d1b8 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -33,4 +33,4 @@ hardening checklist; progress is tracked in [DEFENSE_IN_DEPTH.md](./DEFENSE_IN_D - `.github/CODEOWNERS` names `@jaredwray` for `/.github/`, `/.vscode/`, `/.cursor/`, `/.devcontainer/`, and `/scripts/`. - Codespaces and Cursor Cloud Agents install through Aikido Safe Chain; package-manager shims must not be bypassed. - The Codespaces Dev Container image is pinned by digest (`name:@sha256:`), not a floating tag. -- Aikido scans every build. +- Aikido scans every build. Stage-publish is gated on a passing Aikido `scan-release` job.